Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
All Tools

SOC 2 Readiness Assessment

Answer 10 questions about your current security practices to see how ready you are for a SOC 2 Type II audit.

0%
Recommendations

    Not ready for a call yet?

    Get the compliance playbook

    A few short notes from Jacob on getting audit-ready without months of pain. No fluff, unsubscribe in one click. Reply anytime; it reaches him directly.

    From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.

    Want it done for you?

    SOC 2 in 75 Days

    Readiness, remediation, and auditor coordination in a fixed window.

    Explore SOC 2 in 75 Days →

    Want help getting SOC 2 ready?

    We have helped startups go from zero to an audit-ready SOC 2 program. Our SOC 2 readiness and audit prep engagements, plus auditor management and advocacy, handle the policies, the controls, and the auditor prep so you can keep building product.

    Book a call

    Frequently asked questions

    How accurate is this SOC 2 readiness estimate?

    It gives a directional read on how prepared you are based on the answers you provide. It is a useful starting point, not a substitute for a formal readiness assessment or the auditor's judgment. The real picture comes from reviewing your actual controls and evidence, which we do in a full engagement.

    Is the tool free?

    Yes, it is free to use and no payment is required. It exists to help you understand where you stand before deciding whether to start a readiness project. There is no obligation to engage us afterward.

    What is SOC 2 readiness?

    Readiness is the work of getting your controls, policies, and evidence in place before a SOC 2 audit. It covers gap remediation and evidence collection so the actual audit goes smoothly. The audit itself is performed separately by an independent licensed CPA firm.

    What do I do with my results?

    Use them to see which areas need attention before an audit. If you want help closing the gaps, our SOC 2 in 75 Days track handles readiness and remediation, and we coordinate with the CPA firm that issues your report. Book a call to turn the results into a plan.

    Want the full picture on SOC 2?

    This gives you the shape of the problem. The full picture is all 61 criteria of SOC 2, each one explained in plain English, with somewhere to attach the evidence and a readiness score that moves as you close gaps. Start a free assessment and walk every control.

    Start your free SOC 2 assessment See what is in the Workspace

    No credit card, no trial clock, no locked features. TrazTech makes money when someone wants help closing the gaps, not from the Workspace itself.

    Track record

    Who is actually doing the work

    5
    Published CVEs, including a CVSS 9.1
    76
    Controls taken from nothing to a passed SOC 2 Type II
    Zero
    Exceptions on that Type II report
    20+
    Penetration testing engagements delivered

    Published vulnerability research

    Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

    A SOC 2 Type II built from nothing

    At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.